QID 44093

Date Published: 2023-07-26

QID 44093: Hewlett Packard Enterprise (HPE) ArubaOS Multiple Security Vulnerabilities (ARUBA-PSA-2023-008)

Aruba Networks provides data networking solutions for enterprises and businesses worldwide.

Aruba has released patches for ArubaOS that address multiple security vulnerabilities.
Affected Versions:
ArubaOS 10.4.x.x: 10.4.0.1 and below
ArubaOS 8.11.x.x: 8.11.1.0 and below
ArubaOS 8.10.x.x: 8.10.0.6 and below
ArubaOS 8.6.x.x: 8.6.0.20 and below
The following ArubaOS versions are End of Support are affected by these vulnerabilities and are not patched by this advisory.
ArubaOS 8.9.x.x - All.
ArubaOS 8.8.x.x - All.
ArubaOS 8.7.x.x - All.
ArubaOS 6.5.4.x - All.
QID Detection Logic (Unauthenticated):
This QID gets the vulnerable ArubaOS version via SNMP.
QID Detection Logic(Authenticated):
This will execute the command "show version" and then check the ArubaOS Version.

Successful exploitation of this vulnerability may allow an unauthenticated attacker to execute arbitrary code,unauthenticated Stored Cross-Site Scripting (XSS) on the target system.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Please refer to ARUBA-PSA-2023-008 for more information about patching these vulnerabilities.Workaround:
    To minimize the likelihood of an attacker exploiting thesevulnerabilities, HPE Aruba Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ARUBA-PSA-2023-008 URL Logo www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-008.txt